Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
11 Oct 2017SANTANDER CONSUMER EFC, S.A.SANTANDER CONSUMER EFC, S.A. was fined by the AEPD for sending promotional SMS messages without the recipient’s consent. The authority also noted that the messages were sent despite the recipient’s objection to receiving advertising.ESAEPDePrivacy€8,000
17 May 2023Santander Consumer Bank S.p.A.Santander Consumer Bank S.p.A. was fined by the Garante EUR 10,000 for failing to provide timely and adequate access to personal data. The authority also found that prejudicial information related to a loan was not deleted, constituting a breach of GDPR Article 15.ITGaranteGDPR€10,000
01 Jan 2024Santander BankIn 2024, Santander Bank was fined 1,440,000 PLN by UODO. The sanction concerned the failure to report a personal data breach, which is a significant breach of GDPR obligations.PLUrząd Ochrony Danych OsobowychGDPR€331,000
02 Mar 2011Santa Caterina Impianti S.p.A.Santa Caterina Impianti S.p.A. was fined 12,000 EUR by the Garante. The authority found a breach for failing to provide the required data protection information under the Italian Data Protection Code.ITGaranteGDPR€12,000
02 Oct 2014San Petronio s.r.l.San Petronio s.r.l. was fined by the Garante for failing to appoint data processing officers and for providing inadequate information about video surveillance. The authority found that these practices breached data protection rules.ITGaranteGDPR€10,000
24 Oct 2013SANITAS S.A.SANITAS S.A. was fined by the AEPD in the amount of 1,200 EUR for sending unsolicited commercial emails. The authority found that the required information clause was missing, which constitutes a breach of Article 21 of the LSSI.ESAEPDePrivacy€1,200
03 Mar 2020SANGIL Y GARCÍA, S.L.SANGIL Y GARCÍA, S.L. was fined by the AEPD 1,800 EUR for sending promotional emails using personal data obtained from the Boletín Oficial de la Propiedad Industrial. The company had no prior client relationship with the recipients, which breached data protection rules.ESAEPDePrivacy€1,800
22 Aug 2024Sancțiuni pentru încălcarea RGPDThe ANSPDCP fined the company EUR 3,000 for violating Article 2 of the GDPR. The case concerned non-compliance with data protection requirements.ROANSPDCPGDPR€3,000
16 Mar 2023Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for unauthorized disclosure and access to personal data. The case concerned data confidentiality and breaches of GDPR obligations.ROANSPDCPGDPR€1,000
16 Mar 2023Sancțiuni pentru încălcarea RGPDA healthcare operator was fined for failing to implement adequate security measures, which led to unauthorized access to personal data. The case indicates a breach of data protection obligations under the GDPR.ROANSPDCPGDPR€3,000
25 Jun 2015San Bartolo s.r.l.San Bartolo s.r.l. was fined by the Garante for processing employees’ biometric data without prior notification and without the required preliminary verification. The case concerns a breach of privacy rules governing special-category data.ITGaranteGDPR€24,000
08 Sept 2020Sanatatea Press Group S.R.L.Sanatatea Press Group S.R.L. was fined EUR 2,000 by ANSPDCP for a data security breach during an online event. Login details were mistakenly sent to incorrect email addresses, resulting in disclosure of information to unauthorized recipients.ROANSPDCPGDPR€2,000
10 Sept 2014SAMPLE GESTION S.L.U.SAMPLE GESTION S.L.U. was fined by the AEPD in the amount of 1,100 EUR for sending unsolicited commercial SMS messages despite the recipient's request to opt out. This constituted a breach of Article 21.1 of the LSSI on unsolicited marketing communications.ESAEPDePrivacy€1,100
13 Jun 2024Samodzielny Publiczny Zespół Opieki Zdrowotnej z siedzibą w P., za naruszenie art. 5 ust. 1 lit. f) i ust. 2, art. 25 ust. 1, art. 32 ust. 1 i 2 oraz art. 34 ust. 1 rozporządzenia 2016/679The Polish DPA (UODO) imposed an administrative fine of PLN 40,000 on the Samodzielny Publiczny Zespół Opieki Zdrowotnej based in P. The decision concerns breaches of Article 5(1)(f) and (2), Article 25(1), Article 32(1) and (2), and Article 34(1) of Regulation (EU) 2016/679.PLUODOGDPR€9,201
17 Dec 2024Sambla Group OySambla Group Oy was fined EUR 950,000 by TSV for failing to adequately protect loan applicants' data. The data was accessible to third parties through unique URLs, which breached GDPR requirements on data protection and security.FITSVGDPR€950,000
01 Jan 2025Sambla GroupThe Finnish Data Protection Authority fined Sambla Group EUR 950,000 after unauthorized parties accessed credit application data by manipulating web addresses. The authority found that the company had not implemented adequate safeguards to prevent the breach.FITietosuojavaltuutetun toimistoGDPR€950,000
14 Dec 2017Salvatore AloiSalvatore Aloi was fined EUR 120,000 by the Italian Garante. The case concerned the processing of personal data of 12 individuals without consent, by activating phone cards in their names without authorization.ITGaranteGDPR€120,000
23 Jun 2020SALBEGAP, S.L.SALBEGAP, S.L. was fined by the AEPD EUR 2,000 for installing surveillance cameras in common areas without authorization from the homeowners' association. The authority found that this breached data protection principles.ESAEPDGDPR€2,000
11 Mar 2020SALAD MARKET S.L.SALAD MARKET S.L. was fined by the AEPD €3,000 for using video cameras to monitor employees without informing them. The company also added employees to WhatsApp groups without consent, which breached data protection rules.ESAEPDePrivacy€3,000
04 Oct 2021SAKBO SPAIN, S.L.SAKBO SPAIN, S.L. was fined by the AEPD in the amount of 5,000 EUR for sending unsolicited commercial emails without recipient consent. The conduct breached Article 21 of the LSSI governing electronic marketing communications.ESAEPDePrivacy€5,000